cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3343
Views
3
Helpful
11
Replies

Syslog in RME

sachinraja
Level 9
Level 9

Hello everyone,

I have a small problem with the syslog functionality in RME... I have configured syslog on my switches/routers and directing it to the ciscoworks server. I infact get these syslog messages on the log file generated in cscopx/log directory.. but am not able to see these reports from the "standard reports" tab of the RME. It gives an error message "invalid log file location", whereas, I have given the correct location on the "collector storage option"...

Anything else I can do ?

11 Replies 11

kawng
Level 1
Level 1

Hi there,

You said that it goes to the log file directory?

Which log file is it? syslog.log? and it does match

the full path defined in Change Storage Options.

Are you using the 8.3 notation? ie.

C:\Progra~1\CSCOpx\log\syslog.log

Please clarify

hi kawng,

Yes.. am using this path "C:\Progra~1\CSCOpx\log\syslog.log" on the change storage option tab...

I can see log messages coming on the syslog.log file, but am not able to view using the standard reports..

kawng
Level 1
Level 1

what are the permissions on the log file?

does CASUSER have FULL CONTROL permissions?

Is the SyslogAnalyzer process running?

Please try to stop/restart the process.

Was the location of the file ever changed?

Has Syslog Standard Reports ever worked before?

if yes, when was the last time it worked and

what changed occurred prior to the last time

it worked?

Are all reports getting the same error? ie. 24 hr report, etc.

hi kawng,

here are your answers:

does CASUSER have FULL CONTROL permissions?

Yes.. it has full control..

Is the SyslogAnalyzer process running?

Ans: the CMF syslog service is running... what else should i check to see that the sysloganalyser is running or not..

Was the location of the file ever changed?

Ans: wasnt changed at all.. right now, i had tried changing the file to a different one, called newsyslog.txt and i have changed the mapping on the regedit too.. now, i receive all the messages on this new file, but still not able to view the standard reports..

Has Syslog Standard Reports ever worked before?

havent checked that, because we are just now customizing the ciscoworks here...

Are all reports getting the same error? ie. 24 hr report, etc.

Ans: Interesting thing is that , only the standard report has this error.. even the "severity level report" comes up with some figures , like warnings- 8, debug -7 etc, but when i click on the warnings, to see the logs, it gives me an error...

One thing is that the ciscoworks server is behind a firewall and we have opened UDP 514 on the firewall. the syslog messages are successfully delivered to the ciscoworks server, but we arent able to retrive it locally.. so , i think there is no problem with the firewall in between.. can you confirm ?

Hi,

I've got a similar problem:

My Syslog was working fine for a long time.

I'm running RME 3.5 with IDU10.0 installed.

CiscoWoks installed into D:\CW2000 (not default) directory.

Two weeks ago I installed VMS IDS MC 2.0 update on my CW2000 machine (I know TAC would say it's not supported to run VMS Basic and RME on the same machine, but I need VMS to manage my single IDS and don't have a spare Windows server).

The upgrade included Windows 2000 Service Pack 4.

I noticed yesterday my RME Syslog Analyzer was not able to display any Syslog message.

I tried different windows (standard reports, 24-hour reports, device center) - no success.

It seems like there are no messages in syslog database (I've configured to clear the messages after 7 days).

The syslog.log file is being updated, the syslog.db file is present with today's date.

BUT looking to Syslog Collector Status I see all messages beeing considered "Invalid"!!!

I've found bug CSCdv50844 on CCO with "RME does not recognize syslog message after upgrade" description.

The bug status is Closed with no details.

Anybody could help?

Thanks,

Milan

Any hint in your daemons.log or dmgtd.log ?

robertsd4006
Level 1
Level 1

Are you by chance running VMS on the same server? For example, management console for IDS, firewall or VPN. I had a similar situation - I could see a few switches, mainly CAT OS device but once I removed all traces of the VPN Management Center application it began working correctly. The reason I was given is that VMS has another syslog server in it that was conflicting. So that may be something else to look for - another syslog server embedded in another application. Hope this helps. David

Yes, I'm running VMS and RME on the same machine.

I was afraid of it but when I had installed VMS originally, everything worked fine.

The problem came with VMS MC upgrade form 1.2.3 to 2.0.

Thanks a lot for your advice, I'll try to find the another syslog process.

Regards,

Milan

Was it also necessary to reinstall RME?

BTW, I've got an info that the next VMS version (available Feb 2005) should be able to run on the same machine as RME.

Regards,

Milan

I did not have to reinstall RME. I just uninstalled all the applications that had to do with VMS and it began working correctly. Hope this helps. David

Thanks.

I'll try your way.

Regards,

Milan

Review Cisco Networking for a $25 gift card